
Security Incident Response Analyst
Posted 13 hours ago

Posted 13 hours ago
This is a fully remote position, open to applicants in North Carolina, +1 more state.
• Oversee high-severity investigations across endpoint, identity, email, network, cloud, and SaaS telemetry.
• Construct and support incident timelines while identifying root causes.
• Implement containment measures which include session revocation, credential resets, token invalidation, host isolation, mailbox rule removals, conditional access modifications, and network blocks.
• Conduct eradication and recovery processes, confirm adversary removal, and eliminate persistence strategies.
• Execute log analysis and basic forensics across memory, disk, M365/Entra audit logs, and proxy/firewall/VPN logs.
• Safeguard evidence for legal and regulatory assessment.
• Direct investigations involving PHI/PII related to unauthorized access, data exposure, insider misuse, compromised devices, and third-party vulnerabilities.
• Assess data involvement, access, duration, viewing, and exfiltration; document outcomes for HIPAA breach risk assessments.
• Collaborate with Privacy, Compliance, and Legal teams regarding breach determinations and notifications.
• Oversee the takedown or remediation of exposed data.
• Contribute to DLP, access evaluations, data classification, and secure file-transfer protocols.
• Manage incident communications directed to the CISO, security leadership, business stakeholders, IT, Legal, Privacy, and HR.
• Produce incident reports and conduct post-incident evaluations.
• Coordinate with MDR/MSSP, forensic retainers, cyber insurance providers, vendors, and external partners.
• Adjust and develop SIEM detections and response playbooks.
• Evaluate and decrease false positives, dwell time, and response duration.
• Execute proactive threat hunts and translate findings into detections or fortification suggestions.
• Identify control deficiencies and drive remediation efforts with responsible teams.
• Mentor and assess L1/L2 analyst investigations.
• Maintain runbooks, severity definitions, and escalation protocols.
• Participate in the on-call rotation and facilitate tabletop exercises.
• Minimum of 5 years in security operations or incident response.
• At least 2 years of experience independently leading investigations on high-severity incidents.
• Extensive, practical knowledge in SIEM and detection engineering.
• Proficiency in query languages such as KQL, SPL, or equivalent.
• Experience with correlation logic, detection tuning, and onboarding log sources.
• Familiarity with Microsoft Sentinel, Rapid7 InsightIDR, Splunk, or similar SIEM tools.
• Expertise in Microsoft Entra ID / Active Directory, Conditional Access, MFA, OAuth/consent grants, token and session abuse, privileged access, and offboarding controls.
• Proficient in BEC and phishing investigations, including header/URL/attachment analysis, mail-flow rules, DMARC/DKIM/SPF, secure email gateways, and API-based email security tools.
• Experience in EDR investigation and response, including Defender for Endpoint, CrowdStrike, or similar platforms.
• Knowledge of endpoint persistence and lateral movement tactics.
• Background in analyzing logs from firewalls, proxies, VPNs, and DNS.
• Understanding of network segmentation, C2 patterns, and data exfiltration indicators.
• Familiarity with MITRE ATT&CK framework.
• Strong written communication skills.
• Experience investigating incidents involving PHI/PII or other regulated data, including data exposure scoping and support for breach risk assessments.
• Preferred experience in the healthcare sector and knowledge of HIPAA Privacy/Security Rules, breach notification requirements, and state privacy regulations.
• Cloud incident response experience is a plus.
• Proficiency in scripting languages such as PowerShell, Python, or KQL is preferred.
• Experience with SOAR platforms is advantageous.
• Certifications such as GCIH, GCFA, GCIA, CISSP, or Microsoft SC-200 are preferred.
• Experience managing incidents involving third parties, vendors, or divested/carved-out business units is preferred.
• Coverage for medical, dental, and vision care.
• Paid time off plan.
• 401(k) plan.
• Flexible spending accounts.
• Basic life insurance.
• Short-term and long-term disability coverage.
• Accident insurance.
• Teammate assistance program.
• Paid parental leave.
• Domestic partner benefits.
• Programs focused on mental, physical, and financial well-being.
Live Nation Entertainment
Samsara
Axians Somnitec AG
Axians
Get handpicked remote jobs straight to your inbox weekly.